RFC 4231 test case 1
Key 0x0b repeated 20 times, message “Hi There”: HMAC-SHA256 = b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7.
Generate HMAC-SHA256, SHA-384, SHA-512 or SHA-1 signatures from a message and secret key.
Enter a message and key, then select Generate HMAC.
Runs in your browser — nothing you enter is sent to a server.
HMAC combines a secret key with a hash function to sign a message: anyone with the key can check the message wasn't changed and came from someone who knows the key. Enter the message and key (as text, hex or Base64), choose the hash, and the browser's Web Crypto API computes the HMAC — the same signature webhooks and API requests use.
HMAC = H((K ⊕ opad) ‖ H((K ⊕ ipad) ‖ message))
Key 0x0b repeated 20 times, message “Hi There”: HMAC-SHA256 = b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7.
Compute the HMAC of the raw request body with your webhook secret and compare it with the signature header.
No — it proves integrity and authenticity; the message itself stays readable.
HMAC-SHA256 unless a service specifies otherwise. HMAC-SHA1 is still safe as an HMAC but best avoided in new designs.
Check the key format (text vs hex vs Base64), extra spaces or newlines in the message, and hex vs Base64 output.
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or files, and check a checksum.
Security Tools
Decode a JSON Web Token to read its header and claims, with expiry times in plain language.
Developer Tools
Encode text to Base64 or decode Base64 to text, with full Unicode support and URL-safe output.
Developer Tools
Generate time-based one-time passwords from a 2FA secret or otpauth link, like an authenticator app.
Security Tools